Jump to content

Recommended Posts

Posted (edited)
That I could kind of understand, had fun with the Solus 3 Agent before.

 

 

 

That I can't... just installed Solus3 on a PC with SMB1 disabled on the server as well as the desktop. Fine from Start to Finish and the SOLUS3 Deployment Service states 'Update was successfully installed'.

 

So... working fine for me... Windows Server 2008 R2 Standard and Windows 10 Education 1703.

 

:confused:

We deploy SOLUS usually after we rebuilt a computer. SMB1 gets disabled automatically through Group Policy, but it refused point blank to deploy though our SOLUS3 console. We did it though PDQ Deploy in the end as I created a package on there to deploy it with.

 

Depends what they mean by "it doesnt work"? I cannot see the Network when i ry to push SIMS out to machines - (Environment > Targets > Add > Tick SIMS > Choose Clients > Network Option - Nothing listed.

 

Ours comes up blank as well.

Edited by MrKJLS
Posted
I see SOLUS3 doesn't deploy the agent with SMB1 disabled but not a game changer in a small school as one could install the agent from a shared folder.

 

Surely that can't be... I am sure I installed SIMS on a new Windows 10 Education laptop using Solus3 after disabling SMB1...

 

We disabled SMB1 across our network and now our SOLUS3 doesn't work either. We have nearly 800 PC's and that will be a massive PITA.

 

Can someone at Capita confirm this for us? @PhilNeal

 

I can confirm disabling SMB1 breaks SOLUS3 from being able to view the available 'agents' that the SOLUS3 agent can be deployed to.

Posted
Depends what they mean by "it doesnt work"? I cannot see the Network when i ry to push SIMS out to machines - (Environment > Targets > Add > Tick SIMS > Choose Clients > Network Option - Nothing listed.

Working fine for me

solus.png

 

SIMS has pushed out successfully on a W10 box that definitely has SMB1 disabled.

  • Thanks 1
Posted
Working fine for me

[ATTACH=CONFIG]43321[/ATTACH]

 

SIMS has pushed out successfully on a W10 box that definitely has SMB1 disabled.

 

What happens if you click Network instead of Active Directory?

 

mstsc_2017-05-19_15-31-11.png

Posted
I can confirm disabling SMB1 breaks SOLUS3 from being able to view the available 'agents' that the SOLUS3 agent can be deployed to.

 

So strange... I am seeing the full list of Agents to choose from.

Posted
What happens if you click Network instead of Active Directory?

 

[ATTACH=CONFIG]43322[/ATTACH]

 

Network has never populated for me either. Though Active Directory and Agents do, and I can add computers manually like usual.

Posted (edited)
What happens if you click Network instead of Active Directory?

 

[ATTACH=CONFIG]43322[/ATTACH]

 

Fair point, I get "Browsing for computers.." and then nothing.

But I can't definitely say that's a 'new' thing in any way related to disabling SMBv1. We always add new computers via Active Directory, not Network. So I've never even looked at 'Network' before, let alone deployed by it.

 

Apparently the guy who found the kill switch isn't keeping the reward he's been offered (but might accept the free pizza): 22-year-old Brit MalwareTech to donate $10,000 WannaCry reward to charity - Business Insider

Pretty cool of him. I mean, it's the honourable thing to do, since A) He found it by accident and B) Why the heck not... But I know I'd have a hard time saying no to 10 big ones...

Edited by Garacesh
Posted
Its quite simple really - a giant malware outbreak that has wreaked havoc across the world. Disabling SMB1 is another arrow in the quiver of security. Normal security procedure when there is a threat is to clamp down on everything, and then re-open things once you're happy its safe - disruption or not.

I can understand it IF you had got the malware then yes you would shut everything down to be safe, however if you still have a clean running network why would you take it down? I didn't see Microsoft or any other company shut down their networks. proactive monitoring through it worked for us.

Posted

I can confirm that the client SMB1 is still enabled on our SIMS server however cannot see the entire network. The SMB1 Server protocol is disabled on our SIMS server.

 

Fair point, I get "Browsing for computers.." and then nothing.

But I can't definitely say that's a 'new' thing in any way related to disabling SMBv1. We always add new computers via Active Directory, not Network. So I've never even looked at 'Network' before, let alone deployed by it.

 

That was the way we used to do it when it worked - a couple of weeks ago.

Posted (edited)
I can understand it IF you had got the malware then yes you would shut everything down to be safe, however if you still have a clean running network why would you take it down? I didn't see Microsoft or any other company shut down their networks. proactive monitoring through it worked for us.

A guy on the smb team at Microsoft recommended disabling SMB1 https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/

 

I like proactive maintenance

Edited by MrKJLS
Posted
I'm currently at an intermediate stage, with SMB v1 client disabled on Windows 7/8.1 workstations, SMB v1 disabled altogether (client and server) on Windows 10 and Server 2012 R2 servers (apart from one which runs backups), and SMB v1 server (but not client) disabled on Server 2008 and 2008 R2 servers (due to our backup NASs running v1). Starting to get hard to remember what's what!
Posted
I've heard on the grapevine that certain big name suppliers such as Siemens who the NHS overall pay lots and lots and lots and lots and lots of money to have not exactly been too helpful in sorting out their various potentially insecure gadgets and gizmos in light of the cyber attack!
Posted (edited)

New SMB Worm Uses Seven NSA Hacking Tools. WannaCry Used Just Two

 

Researchers have detected a new worm that is spreading via SMB, but unlike the worm component of the WannaCry ransomware, this one is using seven NSA tools instead of two.

 

The worm's existence first came to light on Wednesday, after it infected the SMB honeypot of Miroslav Stampar, member of the Croatian Government CERT, and creator of the sqlmap tool used for detecting and exploiting SQL injection flaws.

 

EternalRocks uses seven NSA tools

The worm, which Stampar named EternalRocks based on worm executable properties found in one sample, works by using six SMB-centric NSA tools to infect a computer with SMB ports exposed online. These are ETERNALBLUE, ETERNALCHAMPION, ETERNALROMANCE, and ETERNALSYNERGY, which are SMB exploits used to compromise vulnerable computers, while SMBTOUCH and ARCHITOUCH are two NSA tools used for SMB reconnaissance operations.

 

Once the worm has obtained this initial foothold, it then uses another NSA tool, DOUBLEPULSAR, to propagate to new vulnerable machines.

 

The WannaCry ransomware outbreak, which affected over 240,000 victims, also used an SMB worm to infect computers and spread to new victims.

 

Unlike EternalRocks, WannaCry's SMB worm used only ETERNALBLUE for the initial compromise, and DOUBLEPULSAR to propagate to new machines.

 

New evidence suggests most WannaCry victims were running Windows 7, Windows XP is ‘insignificant’

 

It has been one week since the WannaCry ransomware made its way into computers around the globe, but now that the dust has settled, researchers have had time to examine the true impacts. According to new reports, new evidence is suggesting that most WannaCry victims were running Windows 7, meaning that Windows XP is ‘insignificant’ when it comes to the distribution of the ransomware across Windows machines

 

The data fueling the latest reports comes from Kapersky Lab, a Russian multinational cyber security and anti-virus provider. Their data shows that when put all together, about 98% of computers affected by WannaCry were running Windows 7. Windows XP, meanwhile, only accounted for about one in a thousand infections.

 

This latest data raises concerns: while most media emphasis was on Windows XP, Windows 7 was impacted too, and this one is still the most popular version of Windows nearly eight years after its release. It is worth noting that several months ago, Microsoft had issued a patch for recent versions of Windows which was aimed at protecting from the attack, but most administrators could have likely not installed it. Microsoft also recently issued an emergency patch for Windows XP, Windows 8, and Windows Sever 2003, aimed at stopping the exploit, but not before it had already spread worldwide.

Edited by Arthur
Posted

www.theguardian.com/society/2017/may/19/nhs-cyber-attack-ransomware-disruption-breach

 

French researchers have found a way to decrypt Windows computers infected with WannaCry without having to pay the cyber criminals.

 

Their tools, wannakey and wanakiwi, are able to recover the key used to encrypt the files if it is still in the computer’s memory. It can then be used to restore the encrypted files on infected computers.

 

But the security researchers warned that the tools would only work if the computer had not been rebooted. Wannakey works for Windows XP and, as Adrien Guinet, a security expert and developer of the tool, said: “You need some luck for this to work and so it might not work in every case.”

 

Wanakiwi, developed by Benjamin Delpy – who worked on it during in his spare time outside his day job at the Banque de France – has been shown to work on Windows XP and Windows 7, as well as Windows server 2003, and will probably work on Windows Vista and other variants of Windows affected by WannaCry, according to Delpy.

 

Matthieu Suiche, an internationally renowned hacker who collaborated with Guinet and Delpy, said: “This method relies on finding prime numbers in memory if the memory hasn’t be reused. This means that after a certain period of time memory may get reused and those prime numbers may be erased. Also, this means the infected machine should not have been rebooted.”

 

The tools, verified by several independent security researchers, are described as a last-chance way for technicians to save files that are scheduled to be lost for ever, as the deadline for paying the ransom looms for those computers infected a week ago.

Posted

ETERNALBLUE vs Internet Security Suites and nextgen protections

 

Due to the recent #wannacry ransomware events, we initiated a quick test in our lab.

 

Most vendors claim to protect against the WannaDecrypt ransomware, and some even claims they protect against ETERNALBLUE exploit (MS17-010).

 

Unfortunately, our tests shows otherwise. Warning: We only tested the exploit and the backdoor, but not the payload (Wannacry)!

 

We don’t want to disclose our test results until a fair amount of time is given to vendors to patch their product, but meanwhile we feel that we have to inform the public about the risks.

 

The following 3 products protected the system against the ETERNALBLUE exploit installing the DOUBLEPULSAR backdoor:

 

  • ESET Smart Security
  • F-Secure SAFE – but no log/alert on the console
  • Kaspersky Internet Security

Posted
Great, a week or so after the cyber attacks which has made everyone super paranoid our Exchange server security certificate has expired bringing up a security warning every time someone attempts to access Outlook!!!
Posted
Great, a week or so after the cyber attacks which has made everyone super paranoid our Exchange server security certificate has expired bringing up a security warning every time someone attempts to access Outlook!!!

 

Mine did that the other week, I kept putting it off until it ran out on the morning and no one could connect with their devices.

Posted

What's unclear is why many websites claim that Windows 10 wasn't targeted, yet Microsoft did release a patch in March 2017 for it also.

 

Apparently the latest 1703 is immune, but I'm not sure if that's true either!?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...